The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. Exploitation requires enabling manual minify mode and supplying a manual-format minify filename so that the hash is empty and the f_array[] entries are not overwritten before reaching setupSources().
We have discovered 30,439 live websites that are affected by CVE-2026-9282.
| Product | |
| Category | Cache Tools |
| Vulnerable Domains | 30,439 live websites (100% of W3 Total Cache install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 110 versions ( 100% of all versions) |
| 11,676 websites | |
| 3,775 websites | |
| 1,228 websites | |
| 1,154 websites | |
| 1,112 websites | |
| 1,055 websites | |
| 842 websites | |
| 769 websites | |
| 720 websites | |
| 589 websites |
| .com | 14,036 websites |
| .de | 2,426 websites |
| .org | 1,041 websites |
| .nl | 967 websites |
| .co.uk | 789 websites |
| .it | 788 websites |
| .net | 761 websites |
| .se | 685 websites |
| .com.au | 546 websites |
| .ca | 513 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***************.com | *,*** | ||
| ***********.eu | *,*** | ||
| *********.com | *,*** | ||
| ********.com | *,*** | ||
| ************.com | *,*** | ||
| *********.com | *,*** | ||
| **********.com | *,*** | ||
| **********.com | **,*** | ||
| **********.mx | **,*** | ||
| *****************.com | **,*** |
FAQ